VDB
Sign up
HIGH7.3

PYSEC-2026-2639

FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py

Details

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the problem early through a pull request but has not reacted yet.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/metagpt
Introduced in: 0

No fixed version published yet for metagpt (pip). Pin to a known-safe version or switch to an alternative.

References